37-39
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 37 Configuring Clientless SSL VPN
Configuring Application Access
Enabling and Disabling Smart Tunnel Access
By default, smart tunnels are disabled. If you enable smart tunnel access, the user will have to start it
manually, using the
Application Access
>
Start Smart Tunnels
button on the clientless SSL VPN portal
page. If you enter the
smart-tunnel auto-start
list
command described in the previous section instead
of the
smart-tunnel enable
list
command, the user will not have to start smart tunnel access manually.
To enable smart tunnel access, enter the following command in group-policy webvpn configuration
mode or username webvpn configuration mode:
smart-tunnel
[
enable
list |
disable
]
list
is the name of the smart tunnel list already present in the security appliance webvpn configuration.
You cannot assign more than smart tunnel list to a group policy or username. To view the smart tunnel
list entries in the SSL VPN configuration, enter the
show running-config webvpn
command in
privileged EXEC mode.
To remove the
smart-tunnel
command from the group policy or username and inherit the [
no
]
smart-tunnel
command from the default group-policy, use the
no
form of the command.
no smart-tunnel
The following commands assign the smart tunnel list named apps1 to the group policy:
hostname(config-group-policy)#
webvpn
hostname(config-group-webvpn)#
smart-tunnel enable apps1
The following command disables smart tunnel access:
hostname(config-group-webvpn)#
smart-tunnel disable
Application Access User Notes
The following sections provide information about using application access:
•
Closing Application Access to Prevent hosts File Errors
•
Recovering from hosts File Errors When Using Application Access
Note
The security appliance does not support the Microsoft Outlook Exchange (MAPI) proxy. Neither port
forwarding nor the smart tunnel feature that provides application access through a clientless SSL VPN
session supports MAPI. For Microsoft Outlook Exchange communication using the MAPI protocol,
remote users must use AnyConnect.
Closing Application Access to Prevent hosts File Errors
To prevent hosts file errors that can interfere with Application Access, close the Application Access
window properly when you finish using Application Access. To do so, click the close icon.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......